T09 · Insecure Skill Coding Practices
- Location
SKILL.md:88- Finding
Reusable API Signing Secret and Fixed Client Identifier Embedded in Skill Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent marketplace-search purpose, but it embeds reusable YY API signing material and uses broad triggers that can cause external marketplace queries with weak user intent.
Review this before installing. It queries a third-party marketplace using embedded signing material and a shared device identifier, and its broad triggers may contact YY when you only mention certain games or trading terms. Prefer explicit invocation, avoid using it for sensitive account decisions, and install only from a pinned, trusted revision.
SKILL.md:88Reusable API Signing Secret and Fixed Client Identifier Embedded in Skill Instructions
README.md:27Unpinned Installation Through Mutable Remote Sources
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The README instructs users to install and run a remote package via npx skills without pinning an exact version or immutable reference. If the referenced package or its dependency resolution changes or is compromised, users may execute unintended code during installation or use.
The trigger examples include broad phrases such as '买账号' and 'sell account'-style commerce terms that can easily appear in ordinary conversation, causing the skill to activate unintentionally. In this skill's context, accidental activation is more concerning because it can query a third-party marketplace and guide users toward external trading flows, increasing privacy and phishing/external-site exposure risks.
Overly broad triggers such as generic game-trading and commerce terms can cause the skill to activate in conversations that are not explicitly asking to use this marketplace. Unintended activation increases the chance of unsolicited external requests, marketplace redirection, or execution of browsing/open actions in the wrong conversational context.
The skill hard-codes an API signing secret and instructs the agent to use it to access a third-party service. Embedding reusable credentials in distributable skill content exposes the secret to anyone who can read the file, enabling unauthorized API use, abuse of the provider's front-end trust model, and possible rate-limit or account impact against the service.
The activation logic says to trigger merely on mentioned keywords or game names, without requiring a clear request to search the YY marketplace. This weak intent gating can cause the skill to run when a user is just discussing a game, leading to unnecessary third-party queries or browser navigation that the user did not actually request.
The short trigger '代练' is broad enough to appear in general discussion unrelated to invoking this specific skill. In context, short ambiguous triggers contribute to accidental activation and unintended external marketplace lookup behavior.
The trigger set and workflow are heavily tailored to Chinese terms and a YY marketplace context, but the document does not explicitly offer the user a language or locale choice. Under the policy, forcing a specific language or locale without opt-in can be a natural-language policy issue unless clearly documented as region-specific.
The short trigger '陪练' may be used in ordinary conversation and is not specific enough to indicate intent to use this marketplace skill. Because the skill can make network requests and open browser pages, accidental activation has modest but real security and safety implications.
The trigger '道具' is a generic noun likely to occur in many gaming conversations that have nothing to do with a trading marketplace. This increases the chance of the skill activating without clear user intent and initiating third-party queries unnecessarily.
Overly Broad Trigger: '崩坏' is too short and may match unintended inputs
Overly Broad Trigger: '原神' is too short and may match unintended inputs
The trigger '游仓' is short and brand-adjacent but still ambiguous enough to match casual references without a clear request to use the skill. In a skill that can browse and open external pages, such ambiguity increases the likelihood of unintended execution.
No suspicious patterns detected.